Question - Shibboleth SP authentification IIS serveur - Virtual folder Windows - propagation des droits --- Question - Shibboleth SP authentication IIS server - Windows virtual folder - rights propagation
Rod Widdowson
rdw at steadingsoftware.com
Tue Feb 28 17:31:47 UTC 2023
You are wanting impersonation and that it outwith the parameters of the SP. your best bet will be to delegate complete control to the SP and use it to control access, not NTFS.
Alternatively it might be possible to write some sort of IIS filter to convert the information that sp makes available into a ‘impersonate for the duration of this request’ but I have zero insight into how IIS works and the only impersonation I have ever done on Windows has been in kernel model.
Sent from my iPad
> On 28 Feb 2023, at 14:33, Cantor, Scott via users <users at shibboleth.net> wrote:
>
>
>>
>> Is there a way to configure shibboleth so that a user identified by shibboleth on
>> IIS windows in saml is also identified in windows ?
>
> If what I already sent is not what you mean, then the answer is pretty much no.
>
> -- Scott
>
>
>
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list